chore: sync DPA sub-processors from trust center (#22282)

Automated weekly sync of `subprocessors.json` from Twenty's Trust Center
(OneLeet).

This keeps the DPA's Annex C (the SCC Annex III list of Sub-Processors)
in
lockstep with the canonical list at https://trust.twenty.com — the Trust
Center is the single source of truth; this file is generated from it.

**Please review before merging** — confirm the added/removed
Sub-Processors
are expected, and that customers were notified per Section 6.2 where
required.

<!-- This is an auto-generated description by cubic. -->
<a
href="https://cubic.dev/pr/twentyhq/twenty/pull/22282?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->

Co-authored-by: FelixMalfait <6399865+FelixMalfait@users.noreply.github.com>
This commit is contained in:
github-actions[bot]
2026-06-30 11:32:48 +02:00
committed by GitHub
parent d2ca45b66a
commit 92b37c524d
@@ -18,14 +18,6 @@
"processesPii": true,
"vendorUrl": "https://www.anthropic.com"
},
{
"name": "Cal.com",
"services": [
"Cal.com stores customer-owned data such as scheduling events, meeting titles, event times, attendee names and email addresses, and any notes provided. It also stores company-owned data such as user account details, billing information, preferences, and usage logs."
],
"processingLocations": ["US"],
"processesPii": true
},
{
"name": "ClickHouse",
"services": [
@@ -44,22 +36,6 @@
"processesPii": true,
"vendorUrl": "https://www.cloudflare.com"
},
{
"name": "Framer",
"services": [
"Framer stores customer-owned data such as design files, prototypes, project assets, user-generated content, feedback comments, and collaboration history. The platform also stores company-owned data like user account details, subscription information, usage analytics, configuration settings, and internal logs necessary to operate the service."
],
"processingLocations": ["US"],
"processesPii": true
},
{
"name": "Front",
"services": [
"Front stores customer-owned data such as incoming and outgoing emails, chat messages, attachments, contact information, and conversation metadata. It also stores company-owned data like internal communications, team comments, user account details, usage logs, and configuration settings."
],
"processingLocations": ["US"],
"processesPii": true
},
{
"name": "Google Cloud Platform",
"services": [
@@ -69,15 +45,6 @@
"processesPii": true,
"vendorUrl": "https://cloud.google.com"
},
{
"name": "Google Workspace",
"services": [
"Google Workspace stores customer-owned data such as emails and threads in Gmail; documents, spreadsheets, presentations, and forms created or shared via Google Docs, Sheets, Slides and Forms; files and folders uploaded to Google Drive; calendar events, meeting invitations and attendees from Google Calendar; chat messages and history from Google Chat; voice and video recordings and transcripts from Google Meet; contact information; and associated metadata like timestamps, revisions, collaborators, and access permissions. It also stores company-owned data like user account and identity information, billing and payment details, project and organization configurations, usage analytics, security logs, device information, and audit trails needed to provide, secure, and improve the Google Workspace services."
],
"processingLocations": ["US"],
"processesPii": true,
"vendorUrl": "https://workspace.google.com"
},
{
"name": "OpenAI",
"services": [
@@ -95,15 +62,6 @@
"processingLocations": ["US"],
"processesPii": true,
"vendorUrl": "https://sentry.io"
},
{
"name": "Stripe",
"services": [
"Stripe stores customer-owned data such as payment card details (card numbers, expiration dates, CVV tokens), transaction records, charges, refunds, invoices, receipts, subscription information, payment intents, dispute evidence, payout and settlement records, and associated metadata like amounts, currencies, timestamps, merchant IDs and customer identifiers. It also stores customer communication logs, KYC documents and tax forms when required. The service stores company-owned data like user account details, API keys, billing and subscription information, usage analytics, configuration settings, and internal logs used for fraud prevention, risk analysis, and service optimization."
],
"processingLocations": ["US"],
"processesPii": true,
"vendorUrl": "https://stripe.com"
}
]
}